According to TechFlow TechFlow, on December 13th, the 0G Foundation announced on the X platform that a targeted attack on December 11th resulted in the compromise of the rewards contract. Attackers exploited the emergency withdrawal function of the 0G rewards contract used to distribute affiliate rewards, stealing 520,010 0G tokens, 9.93 ETH, and USDT worth $4,200. These tokens were subsequently bridged and distributed via Tornado Cash. Due to a critical vulnerability in Next.js (CVE-2025-66478) exploited on December 5th, attackers moved laterally via internal IP addresses, affecting calibration services, validator nodes, Gravity NFT services, node sales services, computation, Aiverse, Perpdex, Ascend, etc., but the core chain infrastructure and user funds were unaffected.
0G Foundation: Approximately 520,000 0G tokens were stolen from the reward contract 2 days ago.
This article is machine translated
Show original
Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content





